Hi all,
I have events coming in that have multivalue fields, but not always the same fields are multivalue. I want all the fields in the events resulting from a search to be concatenated to single value field.
Example:
Result now shows:
dest xyz
fff
Result should show:
dest xyz [delimiter] fff
Just to be sure that everyone understand using dest here is an example it should be a query that I can run that would actually change every multivalue field regardless of field name.
Cheers,
| foreach *
[| eval <<FIELD>>=mvjoin(<<FIELD>>,",")]
Mind blown! I did not know that foreach existed in Splunk, thanks!